目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CWE-307 过多认证尝试的限制不恰当 类漏洞列表 410

CWE-307 过多认证尝试的限制不恰当 类弱点 410 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-307 属于身份验证缺陷,指系统未有效限制短时间内过多的认证失败尝试。攻击者常利用此漏洞进行暴力破解或字典攻击,通过高频尝试猜测凭证以获取未授权访问。开发者应实施账户锁定机制、引入验证码挑战或设置动态速率限制,从而在保障用户体验的同时,显著增加自动化攻击的难度与成本,确保系统安全性。

MITRE CWE 官方描述
CWE:CWE-307 过度身份验证尝试的限制不当 英文:产品未实施足够的措施来防止在短时间内发生多次失败的身份验证尝试。
常见影响 (1)
Access Control Bypass Protection Mechanism
An attacker could perform an arbitrary number of authentication attempts using different passwords, and eventually gain access to the targeted account using a brute force attack.
缓解措施 (2)
Architecture and Design Common protection mechanisms include: Disconnecting the user after a small number of failed attempts Implementing a timeout Locking out a targeted account Requiring a computational task on the user's part.
Architecture and Design Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482]. Consider using libraries with authentication capabilities such as OpenSSL or the ESAPI Authenticator. [REF-45]
代码示例 (2)
In January 2009, an attacker was able to gain administrator access to a Twitter server because the server did not restrict the number of login attempts [REF-236]. The attacker targeted a member of Twitter's support team and was able to successfully guess the member's password using a brute force attack by guessing a large number of common words. After gaining access as the member of the support st…
The following code, extracted from a servlet's doPost() method, performs an authentication lookup every time the servlet is invoked.
String username = request.getParameter("username"); String password = request.getParameter("password"); int authResult = authenticateUser(username, password);
Bad · Java
CVE ID 标题 CVSS 风险等级 Published
CVE-2026-93650 Saleor throttling.py get_client_ip 认证绕过漏洞 — Saleor 3.7 Low 2026-09-18
CVE-2026-40538 Synology DSM 7.3.2前认证限制不当致文件读取 — DiskStation Manager (DSM) 3.7 Low 2026-09-18
CVE-2026-56592 HCL BigFix Service Management 存在多个安全漏洞 — HCL BigFix Service Management 6.5 Medium 2026-09-18
CVE-2026-92583 AVideo 29.0 非原子计数致速率限制绕过 — AVideo 6.5 Medium 2026-09-16
CVE-2026-91973 Vikunja 授权问题漏洞 — vikunja 7.5 High 2026-09-15
CVE-2026-91972 Vikunja 授权问题漏洞 — vikunja 7.5 High 2026-09-15
CVE-2026-92082 Payara Server 登录无限制致暴力破解漏洞 — Payara Server 6.3 Medium 2026-09-15
CVE-2026-55795 CraftCMS commerce 授权问题漏洞 — commerce 6.9 Medium 2026-09-14
CVE-2026-89174 Kingdom Communication Associated Smart Video Intercom System 授权问题漏洞 — EH3040 7.5 High 2026-09-11
CVE-2026-88770 Keycloak 授权问题漏洞 — Red Hat Build of Keycloak 6.5 Medium 2026-09-10
CVE-2026-78490 Dell Secure Connect Gateway 授权问题漏洞 — Secure Connect Gateway 5.0 - Application 7.5 High 2026-09-09
CVE-2026-86729 WWBN AVideo 授权问题漏洞 — AVideo 7.4 High 2026-09-08
CVE-2026-6223 Bahçelievler Muncipality BiHayat App 授权问题漏洞 — BiHayat App 9.4 Critical 2026-09-07
CVE-2026-20514 MediaTek Chipset 授权问题漏洞 — MediaTek chipset - - 2026-09-07
CVE-2026-20512 MediaTek Chipset 授权问题漏洞 — MediaTek chipset - - 2026-09-07
CVE-2026-86186 WWBN AVideo 授权问题漏洞 — AVideo 6.5 Medium 2026-09-05
CVE-2026-85237 MISP 授权问题漏洞 — misp 8.6 High 2026-09-03
CVE-2026-13348 Schneider Electric PowerChute Serial Shutdown 授权问题漏洞 — PowerChute™ Serial Shutdown 6.9 Medium 2026-09-01
CVE-2026-16675 Rockwell Automation FactoryTalk Activation Manager 授权问题漏洞 — FactoryTalk® Activation Manager 8.5 High 2026-09-01
CVE-2026-82643 WWBN AVideo 授权问题漏洞 — AVideo 6.5 Medium 2026-08-30
CVE-2026-82644 WWBN AVideo 授权问题漏洞 — AVideo 7.5 High 2026-08-30
CVE-2026-76940 Ebyte NE2-D11 授权问题漏洞 — Ebyte NA111-M Firmware 7.5 High 2026-08-27
CVE-2026-18260 Drupal Disable Login Page 安全漏洞 — Disable Login Page - - 2026-08-25
CVE-2026-62862 Typebot 授权问题漏洞 — typebot.io 9.1 Critical 2026-08-25
CVE-2026-78655 Perl Punk::Plugin::TOTP 会话 Cookie 重置导致暴力破解限制绕过漏洞 - - 2026-08-25
CVE-2026-75575 Rocket.Chat 侧信道信息泄露漏洞 — Rocket.Chat 5.3 Medium 2026-08-25
CVE-2026-78551 RansomLook 授权问题漏洞 — ransomlook 8.8 High 2026-08-24
CVE-2026-21755 HCL Hive 授权问题漏洞 — HCL Hive 5.3 Medium 2026-08-24
CVE-2026-76213 Thorsten Rinne phpMyFAQ 授权问题漏洞 — phpMyFAQ 7.4 High 2026-08-19
CVE-2026-73529 Alex Tselegidis Plainpad 授权问题漏洞 — plainpad 5.3 Medium 2026-08-18

CWE-307(过多认证尝试的限制不恰当) 是常见的弱点类别,本平台收录该类弱点关联的 410 条 CVE 漏洞。